CIRCIA, CMMC inch closer with rulemaking marathons nearing crucial stage

Published: Sept. 11, 2023, 11:31 a.m.

b'Cybersecurity requirements for defense contractors and cyber incident reporting requirements for critical infrastructure organizations are both nearing critical junctures after years of discussion and development.\\nThe Cybersecurity and Infrastructure Security Agency is \\u201cfinishing\\u201d the notice of proposed rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act of 2022, CISA Director Jen Easterly said during the Billington Cybersecurity Summit in Washington on Wednesday.\\n\\u201cThat should be out later this year or early next year,\\u201d Easterly said.\\nOnce in effect, the rules will require critical infrastructure entities to report cyber incidents to CISA within 72 hours. It will also require them to report ransomware payments within 24 hours. But first CISA has to go through a complex rulemaking process to define key processes, such as what organizations are required to report cyber incidents and what kind of incidents are covered by the law.\\nLearn more about your ad choices. Visit megaphone.fm/adchoices'